AWS Certified DevOps Engineer Professional Exam Study Guide [DOP-C02]

AWS Certified DevOps Engineer - Professional Study Guide

DOP-C02 Preparation Details

The AWS Certified DevOps Engineer – Professional (DOP-C02) is one of the most challenging professional-tier AWS certifications, designed for engineers with deep experience building, automating, and managing distributed systems on AWS.

Passing DOP-C02 demonstrates expertise across six weighted domains: SDLC automation, configuration management and infrastructure as code, resilient cloud solutions, monitoring and logging, incident and event response, and security and compliance.

This study guide maps every domain, task statement, and individual objective to verified official AWS documentation links, giving you a reliable reference as you prepare for the exam’s 65 scored questions. A scaled score of 750 or higher is required to pass.

AWS DevOps Engineer Prep

UdemyAWS Certified DevOps Engineer Professional
CourseraAWS Certified DevOps Engineer Professional Specialization

Content Domain 1: SDLC Automation (22% of scored content)

Task Statement 1.1: Implement CI/CD pipelines.

Knowledge of: Software development lifecycle (SDLC) concepts, phases, and models

What is AWS CodePipeline?

What is AWS CodeBuild?

What is CodeDeploy?

Knowledge of: Pipeline deployment patterns for single- and multi-account environments

What is AWS CloudFormation?

Managing stacks across accounts and Regions with StackSets

What is AWS Organizations?

Skills in: Configuring code, image, and artifact repositories

What is AWS CodeArtifact?

What is Amazon Elastic Container Registry?

What is Amazon Simple Storage Service?

Skills in: Using version control to integrate pipelines with application environments

What is AWS CodePipeline?

What is AWS CodeBuild?

Skills in: Setting up build processes (for example, AWS CodeBuild)

What is AWS CodeBuild?

What is AWS CodePipeline?

Skills in: Managing build and deployment secrets (for example, AWS Secrets Manager, AWS Systems Manager Parameter Store)

What is AWS Secrets Manager?

AWS Systems Manager Parameter Store

Skills in: Determining appropriate deployment strategies (for example, AWS CodeDeploy)

What is CodeDeploy?

Working with the CodeDeploy agent

Task Statement 1.2: Integrate automated testing into CI/CD pipelines.

Knowledge of: Different types of tests (for example, unit tests, integration tests, acceptance tests, user interface tests, security scans)

What is AWS CodeBuild?

What is AWS CodePipeline?

Knowledge of: Reasonable use of different types of tests at different stages of the CI/CD pipeline

What is AWS CodePipeline?

What is AWS CodeBuild?

Skills in: Running builds or tests when generating pull requests or code merges (for example, CodeBuild)

What is AWS CodeBuild?

What is AWS CodePipeline?

Skills in: Running load/stress tests, performance benchmarking, and application testing at scale

What is AWS CodeBuild?

Amazon EC2 Auto Scaling User Guide

Skills in: Measuring application health based on application exit codes

What is Amazon CloudWatch?

What is AWS CodeBuild?

Skills in: Automating unit tests and code coverage

What is AWS CodeBuild?

What is AWS CodePipeline?

Skills in: Invoking AWS services in a pipeline for testing

What is AWS CodePipeline?

What is AWS Lambda?

What is AWS CodeBuild?

Task Statement 1.3: Build and manage artifacts.

Knowledge of: Artifact use cases and secure management

What is AWS CodeArtifact?

What is AWS Secrets Manager?

What is IAM?

Knowledge of: Methods to create and generate artifacts

What is AWS CodeBuild?

What is AWS CodeArtifact?

What is Image Builder?

Knowledge of: Artifact lifecycle considerations

What is AWS CodeArtifact?

What is Amazon Simple Storage Service?

Skills in: Creating and configuring artifact repositories (for example, AWS CodeArtifact, Amazon S3, Amazon Elastic Container Registry [Amazon ECR])

What is AWS CodeArtifact?

What is Amazon Simple Storage Service?

What is Amazon Elastic Container Registry?

Skills in: Configuring build tools for generating artifacts (for example, CodeBuild, AWS Lambda)

What is AWS CodeBuild?

What is AWS Lambda?

Skills in: Automating Amazon EC2 instance and container image build processes (for example, EC2 Image Builder)

What is Image Builder?

What is Amazon Elastic Container Registry?

What is AWS CodeBuild?

Task Statement 1.4: Implement deployment strategies for instance, container, and serverless environments.

Knowledge of: Deployment methodologies for various platforms (for example, Amazon EC2, Amazon Elastic Container Service [Amazon ECS], Amazon Elastic Kubernetes Service [Amazon EKS], Lambda)

What is CodeDeploy?

What is Amazon ECS?

What is Amazon EKS?

What is AWS Lambda?

Knowledge of: Application storage patterns (for example, Amazon Elastic File System [Amazon EFS], Amazon S3, Amazon Elastic Block Store [Amazon EBS])

What is Amazon Elastic File System?

What is Amazon Simple Storage Service?

What is Amazon Elastic Block Store?

Knowledge of: Mutable deployment patterns in contrast to immutable deployment patterns

What is CodeDeploy?

What is Image Builder?

Knowledge of: Tools and services available for distributing code (for example, CodeDeploy, Image Builder)

What is CodeDeploy?

What is Image Builder?

Skills in: Configuring security permissions to allow access to artifact repositories (for example, AWS Identity and Access Management [IAM], CodeArtifact)

What is IAM?

What is AWS CodeArtifact?

Skills in: Configuring deployment agents (for example, CodeDeploy agent)

What is CodeDeploy?

Working with the CodeDeploy agent

Skills in: Troubleshooting deployment issues

What is CodeDeploy?

What is AWS CodePipeline?

What is AWS CloudFormation?

Skills in: Using different deployment methods (for example, blue/green, canary)

What is CodeDeploy?

What is AWS CodePipeline?

Content Domain 2: Configuration Management and IaC (17% of scored content)

Task Statement 2.1: Define cloud infrastructure and reusable components to provision and manage systems throughout their lifecycle.

Knowledge of: Infrastructure as code (IaC) options and tools for AWS

What is AWS CloudFormation?

What is the AWS CDK?

What is the AWS Serverless Application Model (AWS SAM)?

Knowledge of: Change management processes for IaC-based platforms

What is AWS CloudFormation?

Managing stacks across accounts and Regions with StackSets

What Is AWS Config?

Knowledge of: Configuration management services and strategies

What is AWS Systems Manager?

What is AWS AppConfig?

What Is AWS Config?

Skills in: Composing and deploying IaC templates (for example, AWS Serverless Application Model [AWS SAM], AWS CloudFormation, AWS Cloud Development Kit [AWS CDK])

What is AWS CloudFormation?

What is the AWS CDK?

What is the AWS Serverless Application Model (AWS SAM)?

Skills in: Applying CloudFormation stack sets across multiple accounts and AWS Regions

Managing stacks across accounts and Regions with StackSets

What is AWS Organizations?

What Is AWS Control Tower?

Skills in: Determining optimal configuration management services (for example, AWS OpsWorks, AWS Systems Manager, AWS Config, AWS AppConfig)

What is AWS Systems Manager?

What is AWS AppConfig?

What Is AWS Config?

Skills in: Implementing infrastructure patterns, governance controls, and security standards into reusable IaC templates (for example, AWS Service Catalog, CloudFormation modules, AWS CDK)

What is AWS CloudFormation?

What is the AWS CDK?

What is AWS Service Catalog?

Task Statement 2.2: Deploy automation to create, onboard, and secure AWS accounts in a multi-account or multi-Region environment.

Knowledge of: AWS account structures, best practices, and related AWS services

What is AWS Organizations?

What Is AWS Control Tower?

What is IAM?

Skills in: Standardizing and automating account provisioning and configuration

What is AWS Organizations?

What Is AWS Control Tower?

What is AWS CloudFormation?

Skills in: Creating, consolidating, and centrally managing accounts (for example, AWS Organizations, AWS Control Tower)

What is AWS Organizations?

What Is AWS Control Tower?

Skills in: Applying IAM solutions for multi-account and complex organization structures (for example, SCPs, assuming roles)

What is IAM?

What is AWS Organizations?

What is IAM Identity Center?

Skills in: Implementing and developing governance and security controls at scale (AWS Config, AWS Control Tower, AWS Security Hub, Amazon Detective, Amazon GuardDuty, Service Catalog, SCPs)

What Is AWS Config?

What Is AWS Control Tower?

What is AWS Security Hub?

What is Amazon GuardDuty?

What is Amazon Detective?

What is AWS Service Catalog?

Task Statement 2.3: Design and build automated solutions for complex tasks and large-scale environments.

Knowledge of: AWS services and solutions to automate tasks and processes

What is AWS Systems Manager?

What is Step Functions?

What is AWS Lambda?

Knowledge of: Methods and strategies to interact with the AWS software-defined infrastructure

What is AWS CloudFormation?

What is the AWS CDK?

What is AWS Systems Manager?

Skills in: Automating system inventory, configuration, and patch management (for example, Systems Manager, AWS Config)

What is AWS Systems Manager?

AWS Systems Manager Patch Manager

What Is AWS Config?

Skills in: Developing AWS Lambda function automations for complex scenarios (for example, AWS SDKs, Lambda, AWS Step Functions)

What is AWS Lambda?

What is Step Functions?

Skills in: Automating the configuration of software applications to the desired state (for example, OpsWorks, Systems Manager State Manager)

What is AWS Systems Manager?

AWS Systems Manager State Manager

Skills in: Maintaining software compliance (for example, Systems Manager)

What is AWS Systems Manager?

AWS Systems Manager Patch Manager

What Is AWS Config?

Content Domain 3: Resilient Cloud Solutions (15% of scored content)

Task Statement 3.1: Implement highly available solutions to meet resilience and business requirements.

Knowledge of: Multi-AZ and multi-Region deployments (for example, compute layer, data layer)

What is Amazon RDS?

What is Amazon DynamoDB?

What is Amazon Route 53?

Knowledge of: SLAs

What is Amazon CloudFront?

What is Elastic Load Balancing?

Knowledge of: Replication and failover methods for stateful services

What is Amazon RDS?

What is Amazon Aurora?

What is Amazon DynamoDB?

Knowledge of: Techniques to achieve high availability (for example, Multi-AZ, multi-Region)

What is Elastic Load Balancing?

What is Amazon Route 53?

Amazon EC2 Auto Scaling User Guide

Skills in: Translating business requirements into technical resiliency needs

What is Amazon RDS?

What is Amazon DynamoDB?

What is Elastic Load Balancing?

Skills in: Identifying and remediating single points of failure in existing workloads

What is Amazon CloudWatch?

Amazon EC2 Auto Scaling User Guide

What is Elastic Load Balancing?

Skills in: Enabling cross-Region solutions where available (for example, Amazon DynamoDB, Amazon RDS, Amazon Route 53, Amazon S3, Amazon CloudFront)

What is Amazon DynamoDB?

What is Amazon RDS?

What is Amazon Route 53?

What is Amazon CloudFront?

What is Amazon Simple Storage Service?

Skills in: Configuring load balancing to support cross-AZ services

What is Elastic Load Balancing?

What is Amazon Route 53?

Skills in: Configuring applications and related services to support multiple Availability Zones and AWS Regions while minimizing downtime

What is Amazon RDS?

What is Elastic Load Balancing?

Amazon EC2 Auto Scaling User Guide

What is Amazon Route 53?

Task Statement 3.2: Implement solutions that are scalable to meet business requirements.

Knowledge of: Appropriate metrics for scaling services

What is Amazon CloudWatch?

Amazon EC2 Auto Scaling User Guide

Knowledge of: Loosely coupled and distributed architectures

What is Amazon Simple Queue Service?

What is Amazon Simple Notification Service?

What is Amazon EventBridge?

Knowledge of: Serverless architectures

What is AWS Lambda?

What is Amazon API Gateway?

What is AWS Fargate?

Knowledge of: Container platforms

What is Amazon ECS?

What is Amazon EKS?

Skills in: Identifying and remediating scaling issues

What is Amazon CloudWatch?

Amazon EC2 Auto Scaling User Guide

Skills in: Identifying and implementing appropriate auto scaling, load balancing, and caching solutions

Amazon EC2 Auto Scaling User Guide

What is Elastic Load Balancing?

What is Amazon ElastiCache?

Skills in: Deploying container-based applications (for example, Amazon Elastic Container Service [Amazon ECS], Amazon Elastic Kubernetes Service [Amazon EKS])

What is Amazon ECS?

What is Amazon EKS?

Skills in: Deploying workloads in multiple Regions for global scalability

What is Amazon CloudFront?

What is Amazon Route 53?

What is Amazon DynamoDB?

Skills in: Configuring serverless applications (for example, Amazon API Gateway, AWS Lambda, AWS Fargate)

What is Amazon API Gateway?

What is AWS Lambda?

What is AWS Fargate?

Task Statement 3.3: Implement automated recovery processes to meet RTO and RPO requirements.

Knowledge of: Disaster recovery concepts (for example, RTO, RPO)

What is AWS Backup?

What is Amazon RDS?

What is Amazon Route 53?

Knowledge of: AWS Backup and recovery strategies (for example, pilot light, warm standby)

What is AWS Backup?

What is Amazon RDS?

What is Amazon Aurora?

Knowledge of: Recovery procedures

What is AWS Backup?

What is AWS Systems Manager?

Skills in: Testing failover of Multi-AZ and multi-Region workloads (for example, Amazon RDS, Amazon Aurora, Route 53, CloudFront)

What is Amazon RDS?

What is Amazon Aurora?

What is Amazon Route 53?

What is Amazon CloudFront?

Skills in: Identifying and implementing appropriate cross-Region AWS Backup and recovery strategies (for example, AWS Backup, Amazon S3, AWS Systems Manager)

What is AWS Backup?

What is Amazon Simple Storage Service?

What is AWS Systems Manager?

Skills in: Configuring a load balancer to recover from backend failure

What is Elastic Load Balancing?

What is Amazon Route 53?

Content Domain 4: Monitoring and Logging (15% of scored content)

Task Statement 4.1: Configure the collection, aggregation, and storage of logs and metrics.

Knowledge of: How to monitor applications and infrastructure

What is Amazon CloudWatch?

What is Amazon CloudWatch Logs?

What is AWS CloudTrail?

Knowledge of: Amazon CloudWatch metrics (for example, namespaces, metrics, dimensions, and resolution)

What is Amazon CloudWatch?

What is Amazon CloudWatch Logs?

Knowledge of: Real-time log ingestion

What is Amazon Kinesis Data Streams?

What is Amazon Kinesis Data Firehose?

What is Amazon CloudWatch Logs?

Knowledge of: Encryption options for at-rest and in-transit logs and metrics (for example, client-side and server-side, AWS Key Management Service [AWS KMS])

What is AWS Key Management Service?

What is Amazon CloudWatch Logs?

Knowledge of: Security configurations (for example, IAM roles and permissions to allow for log collection)

What is IAM?

What is Amazon CloudWatch Logs?

Skills in: Securely storing and managing logs

What is Amazon CloudWatch Logs?

What is Amazon Simple Storage Service?

What is AWS Key Management Service?

Skills in: Creating CloudWatch metrics from log events by using metric filters

What is Amazon CloudWatch?

What is Amazon CloudWatch Logs?

Skills in: Creating CloudWatch metric streams (for example, Amazon S3 or Amazon Kinesis Data Firehose options)

What is Amazon CloudWatch?

What is Amazon Kinesis Data Firehose?

Skills in: Collecting custom metrics (for example, using the CloudWatch agent)

What is Amazon CloudWatch?

Collect metrics, logs, and traces using the CloudWatch agent

Skills in: Managing log storage lifecycles (for example, Amazon S3 lifecycles, CloudWatch log group retention)

What is Amazon CloudWatch Logs?

What is Amazon Simple Storage Service?

Skills in: Processing log data by using CloudWatch log subscriptions (for example, Amazon Kinesis, AWS Lambda, Amazon OpenSearch Service)

What is Amazon CloudWatch Logs?

What is Amazon Kinesis Data Streams?

What is AWS Lambda?

What is Amazon OpenSearch Service?

Skills in: Searching log data by using filter and pattern syntax or Amazon CloudWatch Logs Insights

Analyzing log data with CloudWatch Logs Insights

What is Amazon CloudWatch Logs?

Skills in: Configuring encryption of log data (for example, AWS KMS)

What is AWS Key Management Service?

What is Amazon CloudWatch Logs?

Task Statement 4.2: Audit, monitor, and analyze logs and metrics to detect issues.

Knowledge of: Anomaly detection alarms (for example, CloudWatch anomaly detection)

What is Amazon CloudWatch?

Using Amazon CloudWatch alarms

Knowledge of: Common CloudWatch metrics and logs (for example, CPU utilization with Amazon EC2, queue length with Amazon RDS, 5xx errors with an Application Load Balancer [ALB])

What is Amazon CloudWatch?

What is Amazon CloudWatch Logs?

Knowledge of: Amazon Inspector and common assessment templates

What is Amazon Inspector?

Knowledge of: AWS Config rules

What Is AWS Config?

Knowledge of: AWS CloudTrail log events

What is AWS CloudTrail?

Skills in: Building CloudWatch dashboards and Amazon QuickSight visualizations

Using Amazon CloudWatch dashboards

What is Amazon QuickSight?

Skills in: Associating CloudWatch alarms with CloudWatch metrics (standard and custom)

Using Amazon CloudWatch alarms

What is Amazon CloudWatch?

Skills in: Configuring AWS X-Ray for different services (for example, containers, Amazon API Gateway, Lambda)

What is AWS X-Ray?

Skills in: Analyzing real-time log streams (for example, using Amazon Kinesis Data Streams)

What is Amazon Kinesis Data Streams?

What is Amazon CloudWatch Logs?

Skills in: Analyzing logs with AWS services (for example, Amazon Athena, CloudWatch Logs Insights)

What is Amazon Athena?

Analyzing log data with CloudWatch Logs Insights

Task Statement 4.3: Automate monitoring and event management of complex environments.

Knowledge of: Event-driven, asynchronous design patterns (for example, S3 Event Notifications or Amazon EventBridge events to Amazon Simple Notification Service [Amazon SNS] or Lambda)

What is Amazon EventBridge?

What is Amazon Simple Notification Service?

What is Amazon Simple Storage Service?

Knowledge of: Capabilities of auto scaling for a variety of AWS services (for example, EC2 Auto Scaling groups, RDS storage auto scaling, Amazon DynamoDB, Amazon Elastic Container Service [Amazon ECS] capacity provider, Amazon Elastic Kubernetes Service [Amazon EKS] autoscalers)

Amazon EC2 Auto Scaling User Guide

What is Amazon DynamoDB?

What is Amazon ECS?

What is Amazon EKS?

Knowledge of: Alert notification and action capabilities (for example, CloudWatch alarms to Amazon SNS, Lambda, EC2 automatic recovery)

Using Amazon CloudWatch alarms

What is Amazon Simple Notification Service?

What is AWS Lambda?

Knowledge of: Health check capabilities in AWS services (for example, ALB target groups, Amazon Route 53)

What is Elastic Load Balancing?

What is Amazon Route 53?

Skills in: Configuring solutions for auto scaling (for example, DynamoDB, EC2 Auto Scaling groups, RDS storage auto scaling, ECS capacity provider)

Amazon EC2 Auto Scaling User Guide

What is Amazon DynamoDB?

What is Amazon RDS?

What is Amazon ECS?

Skills in: Creating CloudWatch custom metrics and metric filters, alarms, and notifications (for example, Amazon SNS, Lambda)

What is Amazon CloudWatch?

Using Amazon CloudWatch alarms

What is Amazon Simple Notification Service?

Skills in: Configuring S3 events to process log files (for example, by using Lambda) and deliver log files to another destination (for example, OpenSearch Service, CloudWatch Logs)

What is Amazon Simple Storage Service?

What is AWS Lambda?

What is Amazon OpenSearch Service?

What is Amazon CloudWatch Logs?

Skills in: Configuring EventBridge to send notifications based on a particular event pattern

What is Amazon EventBridge?

What is Amazon Simple Notification Service?

Skills in: Installing and configuring agents on EC2 instances (for example, AWS Systems Manager Agent [SSM Agent], CloudWatch agent)

What is AWS Systems Manager?

Collect metrics, logs, and traces using the CloudWatch agent

Skills in: Configuring AWS Config rules to remediate issues

What Is AWS Config?

Skills in: Configuring health checks (for example, Route 53, ALB)

What is Amazon Route 53?

What is Elastic Load Balancing?

Content Domain 5: Incident and Event Response (14% of scored content)

Task Statement 5.1: Manage event sources to process, notify, and take action in response to events.

Knowledge of: AWS services that generate, capture, and process events (for example, AWS Health, Amazon EventBridge, AWS CloudTrail)

What is Amazon EventBridge?

What is AWS CloudTrail?

AWS Health User Guide

Knowledge of: Event-driven architectures (for example, fan out, event streaming, queuing)

What is Amazon EventBridge?

What is Amazon Simple Queue Service?

What is Amazon Kinesis Data Streams?

Skills in: Integrating AWS event sources (for example, AWS Health, EventBridge, CloudTrail)

What is Amazon EventBridge?

What is AWS CloudTrail?

AWS Health User Guide

Skills in: Building event processing workflows (for example, Amazon Simple Queue Service [Amazon SQS], Amazon Kinesis, Amazon Simple Notification Service [Amazon SNS], AWS Lambda, AWS Step Functions)

What is Amazon Simple Queue Service?

What is Amazon Kinesis Data Streams?

What is Amazon Simple Notification Service?

What is AWS Lambda?

What is Step Functions?

Task Statement 5.2: Implement configuration changes in response to events.

Knowledge of: Fleet management services (for example, AWS Systems Manager, AWS Auto Scaling)

What is AWS Systems Manager?

Amazon EC2 Auto Scaling User Guide

Knowledge of: Configuration management services (for example, AWS Config)

What Is AWS Config?

What is AWS Systems Manager?

Skills in: Applying configuration changes to systems

What is AWS Systems Manager?

AWS Systems Manager Automation

Skills in: Modifying infrastructure configurations in response to events

What is Amazon EventBridge?

What is AWS Systems Manager?

What Is AWS Config?

Skills in: Remediating a non-desired system state

What Is AWS Config?

AWS Systems Manager Automation

What is Amazon EventBridge?

Task Statement 5.3: Troubleshoot system and application failures.

Knowledge of: AWS metrics and logging services (for example, Amazon CloudWatch, AWS X-Ray)

What is Amazon CloudWatch?

What is AWS X-Ray?

Knowledge of: AWS service health services (for example, AWS Health, CloudWatch, Systems Manager OpsCenter)

AWS Health User Guide

What is Amazon CloudWatch?

AWS Systems Manager OpsCenter

Knowledge of: Root cause analysis

What is AWS X-Ray?

What is Amazon CloudWatch?

What is Amazon Detective?

Skills in: Analyzing failed deployments (for example, AWS CodePipeline, AWS CodeBuild, AWS CodeDeploy, AWS CloudFormation, CloudWatch synthetic monitoring)

What is AWS CodePipeline?

What is AWS CodeBuild?

What is CodeDeploy?

What is AWS CloudFormation?

Using synthetic monitoring

Skills in: Analyzing incidents regarding failed processes (for example, auto scaling, Amazon Elastic Container Service [Amazon ECS], Amazon Elastic Kubernetes Service [Amazon EKS])

Amazon EC2 Auto Scaling User Guide

What is Amazon ECS?

What is Amazon EKS?

What is Amazon CloudWatch?

Content Domain 6: Security and Compliance (17% of scored content)

Task Statement 6.1: Implement techniques for identity and access management at scale.

Knowledge of: Appropriate usage of different IAM entities for human and machine access (for example, users, groups, roles, identity providers, identity-based policies, resource-based policies, session policies)

What is IAM?

What is IAM Identity Center?

Knowledge of: Identity federation techniques (for example, using IAM identity providers and AWS IAM Identity Center)

What is IAM?

What is IAM Identity Center?

Knowledge of: Permission management delegation by using IAM permissions boundaries

What is IAM?

Permissions boundaries for IAM entities

Knowledge of: Organizational SCPs

What is AWS Organizations?

What is IAM?

Skills in: Designing policies to enforce least privilege access

What is IAM?

Permissions boundaries for IAM entities

What is AWS Organizations?

Skills in: Implementing role-based and attribute-based access control patterns

What is IAM?

What is IAM Identity Center?

Skills in: Automating credential rotation for machine identities (for example, AWS Secrets Manager)

What is AWS Secrets Manager?

Skills in: Managing permissions to control access to human and machine identities (for example, enabling multi-factor authentication [MFA], AWS Security Token Service [AWS STS], IAM profiles)

What is IAM?

What is IAM Identity Center?

What is AWS Secrets Manager?

Task Statement 6.2: Apply automation for security controls and data protection.

Knowledge of: Network security components (for example, security groups, network ACLs, routing, AWS Network Firewall, AWS WAF, AWS Shield)

What is AWS Network Firewall?

What is AWS WAF?

What is AWS Shield?

Knowledge of: Certificates and public key infrastructure (PKI)

What is AWS Certificate Manager?

What is AWS CloudHSM?

Knowledge of: Data management (for example, data classification, encryption, key management, access controls)

What is AWS Key Management Service?

What is Amazon Macie?

What is AWS CloudHSM?

Skills in: Automating the application of security controls in multi-account and multi-Region environments (for example, AWS Security Hub, AWS Organizations, AWS Control Tower, AWS Systems Manager)

What is AWS Security Hub?

What is AWS Organizations?

What Is AWS Control Tower?

What is AWS Systems Manager?

Skills in: Combining security controls to apply defense in depth (for example, AWS Certificate Manager [ACM], AWS WAF, AWS Config, AWS Config rules, Security Hub, Amazon GuardDuty, security groups, network ACLs, Amazon Detective, Network Firewall)

What is AWS Certificate Manager?

What is AWS WAF?

What Is AWS Config?

What is AWS Security Hub?

What is Amazon GuardDuty?

What is Amazon Detective?

What is AWS Network Firewall?

Skills in: Automating the discovery of sensitive data at scale (for example, Amazon Macie)

What is Amazon Macie?

Skills in: Encrypting data in transit and data at rest (for example, AWS Key Management Service [AWS KMS], AWS CloudHSM, ACM)

What is AWS Key Management Service?

What is AWS CloudHSM?

What is AWS Certificate Manager?

Task Statement 6.3: Implement security monitoring and auditing solutions.

Knowledge of: Security auditing services and features (for example, AWS CloudTrail, AWS Config, VPC Flow Logs, AWS CloudFormation drift detection)

What is AWS CloudTrail?

What Is AWS Config?

What is AWS CloudFormation?

Knowledge of: AWS services for identifying security vulnerabilities and events (for example, GuardDuty, Amazon Inspector, IAM Access Analyzer, AWS Config)

What is Amazon GuardDuty?

What is Amazon Inspector?

What is IAM Access Analyzer?

What Is AWS Config?

Knowledge of: Common cloud security threats (for example, insecure web traffic, exposed AWS access keys, S3 buckets with public access enabled or encryption disabled)

What is Amazon GuardDuty?

What is Amazon Macie?

What is AWS Security Hub?

Skills in: Implementing robust security auditing

What is AWS CloudTrail?

What Is AWS Config?

What is AWS Security Hub?

Skills in: Configuring alerting based on unexpected or anomalous security events

What is Amazon GuardDuty?

Using Amazon CloudWatch alarms

What is Amazon EventBridge?

Skills in: Configuring service and application logging (for example, CloudTrail, Amazon CloudWatch Logs)

What is AWS CloudTrail?

What is Amazon CloudWatch Logs?

Skills in: Analyzing logs, metrics, and security findings

What is Amazon CloudWatch?

Analyzing log data with CloudWatch Logs Insights

What is Amazon GuardDuty?

What is AWS Security Hub?

Wrapping Up

This guide has walked through all six content domains of the AWS Certified DevOps Engineer – Professional (DOP-C02) exam, from CI/CD pipeline implementation and infrastructure as code through to security monitoring and compliance automation. Every individual knowledge and skills objective has been broken out with its own set of verified official AWS documentation links.

Use these links as targeted reading alongside hands-on practice — configuring CodePipeline workflows, writing CloudFormation templates, and setting up GuardDuty and Config rules will reinforce the concepts far more than reading alone.

You’ll find study guides for other AWS certifications, including associate and specialty exams, in the AWS certification category. If this guide helped you, feel free to share it or leave a comment below with any questions about your DOP-C02 preparation.

Follow Me to Receive Updates on DOP-C02 Exam


Want to be notified as soon as I post? Subscribe to the RSS feed / leave your email address in the subscribe section. Share the article to your social networks with the below links so it can benefit others.

Share the DOP-C02 Study Guide in Your Network

You may also like